MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 64e277226ed8348102a4af90ee5cfd3624712a5376c447e16b72377c9d6c3acb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry

Intelligence File information 2 Yara Comments

SHA256 hash: 64e277226ed8348102a4af90ee5cfd3624712a5376c447e16b72377c9d6c3acb
SHA1 hash: e73c944922084bc3ce3882721a46a25629682f1c
MD5 hash: 202529ddb3ac1bfcd6141245e249d796
Download: download sample
Signature GuLoader
File size:94'208 bytes
First seen:2020-05-22 19:43:21 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 42c0120e19a589206fe92cac54611eb5
ssdeep 768:4KRI2aAQX4Hez3FBoW28X6+cZTM4UC8lNXjvcttR4FO81maxXbdnDlKZz+q:9RIrX4+zfoWn684UC8bTvFF7xXFkZz7
TLSH 139329A5B961E8A5D8200BF15D778768246BBC341F010B0F74DDBB2E6933D4D897A32B
Reporter @SecuriteInfoCom


Mail intelligence No data
# of uploads 1
# of downloads 23
Origin country US US
ClamAV PUA.Win.Packer.ProtectSharewar-2
VirusTotal:Virustotal results 14.29%

File information

The table below shows additional information about this malware sample such as delivery method and external references.

Web download


Executable exe 64e277226ed8348102a4af90ee5cfd3624712a5376c447e16b72377c9d6c3acb

(this sample)

Delivery method
Distributed via web download